75 Total CVEs
75 AI Analyzed
0 CISA KEV
36 Critical

Profile

0% ended up actively exploited 0 of 75 added to CISA KEV
48% rated critical (CVSS 9.0+) 36 critical, 39 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

75 CVEs in the last 12 months

Products

  • siyuan34
  • SiYuan22
  • SiYuan Note4
  • SiYuan Knowledge Management System2
  • SiYuan Desktop Client1
  • endpoint bypasses1

6 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-75 of 75 CVEs
CVE-2026-85175
Analyzed
8.8
siyuan-note siyuan

SiYuan versions <= 3.8.1 (fixed in v3.8.2) contain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), which onl...

2026-09-04
CVE-2026-85174
Analyzed
8.8
siyuan-note siyuan

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresho...

2026-09-04
CVE-2026-82654
Analyzed
8.9
siyuan-note siyuan

SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can...

2026-08-31
CVE-2026-82653
Analyzed
8.9
siyuan-note siyuan

SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are inte...

2026-08-31
CVE-2026-82649
Analyzed
7
siyuan-note SiYuan Note

SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS ins...

2026-08-31
CVE-2026-82234
Analyzed
8.2
siyuan-note siyuan

SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resol...

2026-08-29
CVE-2026-75917
Analyzed
8.6
siyuan-note siyuan

SiYuan before v3

2026-08-21
CVE-2026-75916
Analyzed
8.6
siyuan-note SiYuan

SiYuan through 3

2026-08-21
CVE-2026-74868
Analyzed
7.5
siyuan-note SiYuan Note

SiYuan versions before 3

2026-08-18
CVE-2026-74802
Analyzed
8.2
siyuan-note SiYuan

SiYuan versions before 3

2026-08-18
CVE-2026-74801
Analyzed
8.2
siyuan-note SiYuan

SiYuan before 3

2026-08-18
CVE-2026-74800
Analyzed
9
siyuan-note siyuan

SiYuan versions before 3.7.4 are vulnerable to stored cross-site scripting due to missing security headers when serving user-uploaded assets, allowing...

2026-08-18
CVE-2026-74799
Analyzed
9.3
siyuan-note siyuan

SiYuan versions before 3.7.4 expose unauthenticated Go debug endpoints, allowing remote attackers to extract sensitive in-memory data such as API keys...

2026-08-18
CVE-2026-74798
Analyzed
8.7
siyuan-note siyuan

SiYuan kernel before v3

2026-08-18
CVE-2026-73608
Analyzed
8.6
siyuan-note siyuan

SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3

2026-08-15
CVE-2026-73056
Analyzed
9.8
siyuan-note siyuan

The SiYuan kernel before 3.7.4 fails to restrict excessive authentication attempts, allowing unauthenticated attackers to brute-force API tokens and g...

2026-08-17
CVE-2026-73054
Analyzed
7.5
siyuan-note SiYuan

SiYuan versions before v3

2026-08-16
CVE-2026-73053
Analyzed
9
siyuan-note siyuan

SiYuan versions before 3.7.4 are susceptible to cross-site scripting in the unicode2Emoji function, allowing arbitrary code execution in the renderer.

2026-08-16
CVE-2026-73052
Analyzed
9
siyuan-note siyuan

A stored cross-site scripting vulnerability in SiYuan allows authenticated attackers to execute arbitrary JavaScript by injecting malicious markup int...

2026-08-16
CVE-2026-73050
Analyzed
9
siyuan-note siyuan

SiYuan before v3.7.4 contains a stored Cross-site Scripting vulnerability in the attribute-view select option color field, allowing arbitrary JavaScri...

2026-08-16
CVE-2026-73046
Analyzed
9.8
siyuan-note siyuan

The SiYuan CheckAuth middleware fails to enforce rate limiting or account lockout for HTTP Basic Authentication, allowing unauthenticated attackers to...

2026-08-16
CVE-2026-73045
Analyzed
7.5
siyuan-note SiYuan

SiYuan before 3

2026-08-16
CVE-2026-73044
Analyzed
9
siyuan-note siyuan

SiYuan versions before 3.7.4 are vulnerable to stored cross-site scripting via the setAttrViewColWidth API, which can lead to arbitrary code execution...

2026-08-16
CVE-2026-73043
Analyzed
9
siyuan-note siyuan

SiYuan versions before 3.7.4 contain a remote code execution vulnerability in the Template calculation operator, allowing execution of arbitrary code...

2026-08-16
CVE-2026-73042
Analyzed
9
siyuan-note siyuan

SiYuan before v3.7.4 is vulnerable to stored Cross-site Scripting via improperly escaped database menu metadata, allowing execution of arbitrary code...

2026-08-16
CVE-2026-73041
Analyzed
9
siyuan-note siyuan

SiYuan versions before 3.7.4 allow arbitrary code execution via malicious PDF annotations that trigger script execution in the PDF renderer with Node....

2026-08-16
CVE-2026-72811
Analyzed
10
siyuan-note siyuan

SiYuan versions up to v3.7.2 are vulnerable to SQL injection via the backlink/mention search query due to improper sanitization of single quotes in cl...

2026-08-15
CVE-2026-72810
Analyzed
8.6
siyuan-note siyuan

SiYuan versions before v3

2026-08-15
CVE-2026-69086
Analyzed
7.7
siyuan-note siyuan

SiYuan versions before v3

2026-08-04
CVE-2026-69085
Analyzed
10
siyuan-note siyuan

SiYuan contains a SQL injection vulnerability in the searchDocs endpoint, allowing unauthenticated attackers to read and modify database content via s...

2026-08-04
CVE-2026-69084
Analyzed
10
siyuan-note siyuan

A critical SQL injection vulnerability in the SiYuan /api/search/searchEmbedBlock endpoint allows unauthenticated remote attackers to execute arbitrar...

2026-08-04
CVE-2026-69083
Analyzed
10
siyuan-note siyuan

A critical SQL injection vulnerability in the SiYuan fullTextSearchAssetContent endpoint allows unauthenticated attackers to read, modify, or delete d...

2026-08-04
CVE-2026-68587
Analyzed
8.6
siyuan-note siyuan

SiYuan versions before v3

2026-08-04
CVE-2026-68586
Analyzed
8.6
siyuan-note siyuan

SiYuan before v3

2026-08-04
CVE-2026-68584
Analyzed
8.6
siyuan-note siyuan

SiYuan versions before v3

2026-08-04
CVE-2026-66396
Analyzed
8.4
siyuan-note siyuan

SiYuan before v3

2026-07-28
CVE-2026-66395
Analyzed
9.6
siyuan-note SiYuan

A reflected cross-site scripting vulnerability in SiYuan desktop allows attackers to achieve remote code execution through malicious deep links that l...

2026-07-28
CVE-2026-66394
Analyzed
8.7
siyuan-note SiYuan

SiYuan before v3

2026-07-28
CVE-2026-66012
Analyzed
10
siyuan-note siyuan

SiYuan before 3.7.2 is vulnerable to missing authorization in the POST /mcp endpoint, allowing unauthenticated remote attackers to achieve full system...

2026-07-26
CVE-2026-65606
Analyzed
9.6
siyuan-note siyuan

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in its protocol handler, enabling remote code execution due to improper handling of...

2026-07-24
CVE-2026-65605
Analyzed
9.6
siyuan-note siyuan

SiYuan before v3.7.2 is vulnerable to stored cross-site scripting in Attribute View, which can be leveraged to achieve arbitrary command execution due...

2026-07-24
CVE-2026-60084
Analyzed
8.7
siyuan-note siyuan

SiYuan versions before v3

2026-08-23
CVE-2026-59855
Analyzed
8.6
siyuan-note SiYuan

SiYuan is an open-source personal knowledge management system

2026-07-10
CVE-2026-59833
Analyzed
8.6
siyuan-note siyuan

SiYuan is an open-source personal knowledge management system

2026-07-10
CVE-2026-59832
Analyzed
7.7
siyuan-note SiYuan

SiYuan is an open-source personal knowledge management system

2026-07-10
CVE-2026-54759
Analyzed
8.7
siyuan-note SiYuan Note

SiYuan is an open-source personal knowledge management system

2026-06-25
CVE-2026-54158
Analyzed
9.9
siyuan-note SiYuan

A critical XSS vulnerability in SiYuan's attribute-view cell renderer allows attackers to inject malicious scripts, leading to remote code execution o...

2026-06-25
CVE-2026-54069
Analyzed
9.2
siyuan-note SiYuan Note

The SiYuan kernel HTTP server improperly trusts browser extension origins, allowing unauthenticated administrative API access and potential data exfil...

2026-06-25
CVE-2026-54067
Analyzed
9.9
siyuan-note SiYuan

A cross-site scripting (XSS) vulnerability in SiYuan's CSS snippet rendering allows attackers to execute arbitrary JavaScript, leading to remote code...

2026-06-25
CVE-2026-50551
Analyzed
9.9
siyuan-note SiYuan

A stored cross-site scripting (XSS) vulnerability in the SiYuan Attribute View allows for remote code execution (RCE) within the Electron desktop clie...

2026-06-25
CVE-2026-45375
Analyzed
9
siyuan-note SiYuan

A stored Cross-Site Scripting (XSS) vulnerability in the SiYuan Marketplace allows attackers to execute arbitrary HTML/JS via malicious package metada...

2026-05-15
CVE-2026-44586
Analyzed
8.3
siyuan-note Multiple Products

SiYuan is an open-source personal knowledge management system

2026-05-15
CVE-2026-41421
Analyzed
8.8
siyuan-note Multiple Products

SiYuan is an open-source personal knowledge management system

2026-04-25
CVE-2026-40322
Analyzed
9
siyuan-note SiYuan

SiYuan versions 3.6.3 and below are vulnerable to stored XSS in Mermaid diagrams, which can be escalated to arbitrary code execution on Electron-based...

2026-04-17
CVE-2026-40318
Analyzed
8.5
siyuan-note Multiple Products

SiYuan is an open-source personal knowledge management system

2026-04-17
CVE-2026-40259
Analyzed
8.1
siyuan-note Multiple Products

SiYuan is an open-source personal knowledge management system

2026-04-17
CVE-2026-39846
Analyzed
9
siyuan-note SiYuan Desktop Client

SiYuan personal knowledge management system is vulnerable to stored XSS, which can lead to remote code execution in the Electron desktop client.

2026-04-08
CVE-2026-34585
Analyzed
8.6
siyuan-note Multiple Products

SiYuan is a personal knowledge management system

2026-04-01
CVE-2026-34453
Analyzed
7.5
siyuan-note Multiple Products

SiYuan is a personal knowledge management system

2026-04-01
CVE-2026-34449
Analyzed
9.6
siyuan-note SiYuan

SiYuan desktop application is vulnerable to Remote Code Execution via a permissive CORS policy. A malicious website can inject JavaScript into the Ele...

2026-04-01
CVE-2026-34448
Analyzed
9
siyuan-note SiYuan

SiYuan is vulnerable to a stored XSS-to-RCE chain in its Attribute View. Malicious URLs in the mAsse field trigger JavaScript execution with full OS a...

2026-04-01
CVE-2026-33670
Analyzed
9.8
siyuan-note SiYuan

SiYuan versions prior to 3.6.2 allow unauthenticated directory traversal and filename retrieval via the /api/file/readDir interface, exposing the stru...

2026-03-27
CVE-2026-33669
Analyzed
9.8
siyuan-note SiYuan

SiYuan versions prior to 3.6.2 are vulnerable to unauthorized data access where document IDs and content can be retrieved through the /api/file/readDi...

2026-03-27
CVE-2026-33476
Analyzed
7.5
siyuan-note SiYuan Knowledge Management System

SiYuan is a personal knowledge management system

2026-03-22
CVE-2026-33203
Analyzed
7.5
siyuan-note SiYuan Knowledge Management System

SiYuan is a personal knowledge management system

2026-03-22
CVE-2026-32940
Analyzed
9.3
siyuan-note SiYuan

SiYuan versions 3.6.0 and below contain a click-through XSS vulnerability in the dynamic icon API due to incomplete SVG sanitization.

2026-03-20
CVE-2026-32938
Analyzed
9.9
siyuan-note SiYuan

SiYuan versions 3.6.0 and below are vulnerable to path traversal and sensitive file exfiltration via improper validation of file:// links in pasted HT...

2026-03-20
CVE-2026-32767
Analyzed
9.8
siyuan-note endpoint bypasses

SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSe...

2026-03-20
CVE-2026-32749
Analyzed
7.6
siyuan-note Multiple Products

SiYuan is a personal knowledge management system

2026-03-20
CVE-2026-32110
Analyzed
8.3
siyuan-note Multiple Products

SiYuan is a personal knowledge management system

2026-03-12
CVE-2026-30926
Analyzed
7.1
siyuan-note Multiple Products

SiYuan is a personal knowledge management system

2026-03-10
CVE-2026-30869
Analyzed
9.3
siyuan-note Multiple Products

SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoint allows an attacker to read a...

2026-03-11
CVE-2026-29183
Analyzed
9.3
siyuan-note SiYuan

SiYuan versions prior to 3.5.9 contain an unauthenticated reflected XSS vulnerability in the dynamic icon API endpoint, allowing JavaScript execution...

2026-03-07
CVE-2026-25539
Analyzed
9.1
siyuan-note SiYuan

SiYuan's /api/file/copyFile endpoint fails to validate the 'dest' parameter, allowing authenticated users to write files to arbitrary locations, poten...

2026-02-05
CVE-2025-67488
Analyzed
7.8
siyuan-note Multiple Products

SiYuan is self-hosted, open source personal knowledge management software

2025-12-11